According to Adi Ruppin, CEO of Espresso Labs, writing in a sponsored Help Net Security post, most compliance work goes into proving security rather than improving it. He cites the Pentagon’s estimate of roughly $105,000 over three years for a small contractor’s CMMC Level 2 compliance—and notes that figure only covers assessment and attestation, not implementing controls. Full first-year programs for small and midsize businesses run from $50,000 to over $300,000, he says. The July suspension of CMMC Phase 2 by the Department of War eased the assessment requirement, but the underlying obligations remain.
AI compliance tools shift from dashboards to continuous enforcement
A sponsored analysis argues that AI-native platforms can close the gap between audit evidence and actual security controls.
More in Security & Privacy
Threats Roundup: Rogue Ransomware, Malicious VS Code Themes, and PQC Gaps
A weekly roundup of security stories shows attackers exploiting both elaborate multi-stage chains and simple configuration mistakes.
Coalition seizes hacking tools tied to China's Flax Typhoon
A multinational operation seized infrastructure behind two hacking tools used by a Chinese cybersecurity firm working for Beijing's Ministry of State Security.
Lawmakers urge Google to halt Spirit Airlines data deal for AI training
More than 100 U.S. lawmakers warn that de-identified employee data from defunct Spirit Airlines could still expose privacy in Google's AI training deal.
AWS Bedrock AgentCore Flaw Could Let One Chatbot Take Over Entire Fleet
A patched vulnerability in AWS Bedrock AgentCore showed how a single malicious prompt to one AI agent could compromise an organization's whole AWS environment.